Framed payment pages

ashcroft_s

Free Member
Dec 23, 2012
12
0
Got a merchant (not the same one as in the 'advice needed on shopping cart' thread...) who is using a hosted payment page solution but within an iframe on their site.

I'm trying to convince them that this is a bad idea. Even though the hosted payment page is run from a secure server, the customer gets no indication of this as it is only displayed in a iframe - so their browser still shows the sites normal (http) url. No amount of 'this is a secure page, honest guv' type text or images you add can really show to the customer that it is a genuine secure payment page on an approved payment provider.

I know the data within that iframe is secure, and as it's a different domain anything outside the iframe can't read any data etc inside the iframe. My concern is all about the customers' re-assurance that things are indeed secure.

Does anyone know of any reports or similar on this sort of approach that I can show to the merchant to try and convince them that they are better off using the hosted payment page as a full page and not in a frame - as in that way the customer gets to see in their browser that they are indeed on a secure site etc.
 
Last edited:

ashcroft_s

Free Member
Dec 23, 2012
12
0
That's an idea - hadn't thought of that for some reason. It's not exactly expensive to get a basic SSL cert, and that would at least show the customer a secure URL when they get to the point of entering their card details.

It's always the simple answers that are the best!
 
Upvote 0

Alan

Free Member
  • Aug 16, 2011
    7,089
    1,974
    Well if you are using Sagepays inframe solution they say

    "For added shopper confidence when making a purchase on your website you should consider an SSL certificate a requirement when using our Server & inFrame integration method."
     
    Upvote 0

    Latest Articles